Other than the primitive IAM roles that apply to all project resources (owner, editor, viewer), Cloud SQL supports four IAM roles:
- roles/cloudsql.admin: Full control, except the ability to connect as a client
- roles/cloudsql.editor: Ability to perform operational tasks on an instance
- roles/cloudsql.viewer: Read-only access to all resources
- roles/cloudsql.client: Ability to connect to an instance via the Cloud SQL Proxy